Security design of remote maintenance system for nuclear power plants based on ISO/IEC 15408

被引:0
|
作者
Watabe, Ryosuke
Oi, Tadashi
Endo, Yoshio
机构
关键词
instrumentation and control system; remote maintenance system; nuclear power plants; ISO/IEC; 15408; security target; protection profile;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As a method to reduce periodic inspection time and mean recovery time on fault occurrence, remote maintenance systems for nuclear power plants (NPPs) are proposed, which augment efficiencies in maintenance operations for the plants by surveying them remotely and achieving collaborations between on-site operators and remote plant designers and expert operators [1]. In particular, with the spread of Internet technology and Internet security protection technology in recent years, there is a tendency to build remote maintenance systems using the Internet without dedicated communication lines [2]. However, the biggest concern of customers such as electric power companies is security. It is highly necessary to give assurance of the security of remote maintenance systems coherently and consistently in order to introduce such systems based on Internet technology into NPPs. However, there exist various ways of thinking about security. Furthermore, there has not been a general agreement on how to give assurance of the security of remote maintenance systems for NPPs. So we have applied ISO/IEC 15408 [3] to remote maintenance systems for NPPs. It is used to evaluate the security level of IT products and systems. Based on ISO/IEC 15408, we have listed assets to be protected, threats to the assets, security objectives against the threats, and security functional requirements that achieve the security objectives. Also, we have shown relations between the threats and the security objectives, and relations between the security objectives and the security functional requirements. As a result, we have concretized a necessary and sufficient security design of remote maintenance systems for NPPs that can protect the instrumentation and control (I&C) system against intrusion, impersonation, tapping, obstruction and destruction. In this paper, we describe the background of the remote maintenance systems for NPPs, a summary of the systems, and its security design based on ISO/IEC 15408.
引用
收藏
页码:1695 / 1699
页数:5
相关论文
共 50 条
  • [1] Development of Supporting Environment for IT System Security Evaluation Based on ISO/IEC 15408 and ISO/IEC 18045
    Bao, Da
    Sun, Wen
    Goto, Yuichi
    Cheng, Jingde
    [J]. 2018 IEEE SMARTWORLD, UBIQUITOUS INTELLIGENCE & COMPUTING, ADVANCED & TRUSTED COMPUTING, SCALABLE COMPUTING & COMMUNICATIONS, CLOUD & BIG DATA COMPUTING, INTERNET OF PEOPLE AND SMART CITY INNOVATION (SMARTWORLD/SCALCOM/UIC/ATC/CBDCOM/IOP/SCI), 2018, : 204 - 209
  • [2] A Supporting Tool for IT System Security Specification Evaluation Based on ISO/IEC 15408 and ISO/IEC 18045
    Bao, Da
    Goto, Yuichi
    Cheng, Jingde
    [J]. TRENDS AND APPLICATIONS IN KNOWLEDGE DISCOVERY AND DATA MINING: PAKDD 2019 WORKSHOPS, 2019, 11607 : 3 - 14
  • [3] Advanced Security Assurance Case Based on ISO/IEC 15408
    Potii, Oleksandr
    Illiashenko, Oleg
    Komin, Dmitry
    [J]. THEORY AND ENGINEERING OF COMPLEX SYSTEMS AND DEPENDABILITY, 2015, 365 : 391 - 401
  • [4] A security requirement management database based on ISO/IEC 15408
    Morimoto, S
    Horie, D
    Cheng, JD
    [J]. COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2006, PT 3, 2006, 3982 : 1 - 10
  • [5] GEST: A Generator of ISO/IEC 15408 Security Target Templates
    Horie, Daisuke
    Yajima, Kenichi
    Azimah, Noor
    Goto, Yuichi
    Cheng, Jingde
    [J]. COMPUTER AND INFORMATION SCIENCE 2009, 2009, 208 : 149 - 158
  • [6] Supporting Verification and Validation of Security Targets with ISO/IEC 15408
    Bao, Da
    Miura, Junichi
    Zhang, Ning
    Goto, Yuichi
    Cheng, Jingde
    [J]. PROCEEDINGS 2013 INTERNATIONAL CONFERENCE ON MECHATRONIC SCIENCES, ELECTRIC ENGINEERING AND COMPUTER (MEC), 2013, : 2621 - 2628
  • [7] An ISO/IEC 15408-2 Compliant Security Auditing System with Blockchain Technology
    Cha, Shi-Cho
    Yeh, Kuo-Hui
    [J]. 2018 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2018,
  • [8] Evaluating the security levels of the Web-Portals based on the standard ISO/IEC 15408
    Hoang Dang Hai
    Pham Thieu Nga
    [J]. PROCEEDINGS OF THE NINTH INTERNATIONAL SYMPOSIUM ON INFORMATION AND COMMUNICATION TECHNOLOGY (SOICT 2018), 2018, : 463 - 469
  • [9] Analysis the priority of security requirement items for the process improvement by ISO/IEC 15504 and ISO/IEC 15408
    Lee, Eun-Ser
    Kim, Haeng-Kon
    Hwang, Sun-Myoung
    [J]. SERA 2007: 5TH ACIS INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING RESEARCH, MANAGEMENT, AND APPLICATIONS, PROCEEDINGS, 2007, : 25 - +
  • [10] A web user interface of the security requirement management database based on ISO/IEC 15408
    Horie, Daisuke
    Morimoto, Shoichi
    Cheng, Jingde
    [J]. COMPUTATIONAL SCIENCE - ICCS 2006, PT 4, PROCEEDINGS, 2006, 3994 : 797 - 804